Vulnerability

CVE-2002-2103

MEDIUM 5.0

CVE-2002-2103 is a medium-severity vulnerability (CVSS v2 5.0). As of 2026-10-08, 145 hosts in our data show software it affects on an open service in at least 15 countries.

Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.

Published
2002-12-31
Last modified
2026-06-16
CVSS score
5.0 CVSS v2
CVSS vector (v2)
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploit likelihood (EPSS)
6.1% in the next 30 days (higher than 93% of CVEs)

Exposure in our data

145 hosts

Hosts whose banner shows an affected software version on a service open at their latest check.

Not counted: 4 hosts with this CVE only from an older observation.

Not counted: 8 more on distribution builds that may be patched (the distribution may have backported the fix without changing the version).

1 more host had it earlier (the software version has since changed or the service is gone).

Counted 2026-10-08 03:20 UTC

By country

United States US52
Germany DE16
Spain ES9
Sweden SE9
Thailand TH7
Australia AU6
Italy IT5
Switzerland CH4
India IN4
Japan JP4
Hong Kong HK3
Brazil BR2
Estonia EE2
France FR2
Ireland IE2

Affected software seen

http_server 1.3.2349
http_server 1.3.2025
http_server 1.3.1923
http_server 1.3.1121
http_server 1.3.1211
http_server 1.3.2210
http_server 1.3.94
http_server 1.3.172